CVE-2020-28851
Summary
| CVE | CVE-2020-28851 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-02 06:15:00 UTC |
| Updated | 2021-02-22 19:14:00 UTC |
| Description | In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.) |
Risk And Classification
Problem Types: CWE-129
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| January 2021 Golang Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| x/text: panic in language.ParseAcceptLanguage while parsing -u- extension · Issue #42535 · golang/go · GitHub | MISC | github.com | Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160173 Oracle Enterprise Linux Security Update for git-lfs (ELSA-2022-7129)
- 160293 Oracle Enterprise Linux Security Update for podman (ELSA-2022-7954)
- 180747 Debian Security Update for golang-golang-x-text (CVE-2020-28851)
- 199182 Ubuntu Security Notification for Go Text Vulnerabilities (USN-5873-1)
- 240773 Red Hat Update for git-lfs (RHSA-2022:7129)
- 240876 Red Hat Update for podman (RHSA-2022:7954)
- 377746 Alibaba Cloud Linux Security Update for git-lfs (ALINUX3-SA-2022:0180)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 940722 AlmaLinux Security Update for git-lfs (ALSA-2022:7129)
- 940834 AlmaLinux Security Update for podman (ALSA-2022:7954)